Skip to main content
Every Public API request requires a user API token created from Settings → Public API in the PostlyBee dashboard. Tokens can access every managed workspace or an explicit workspace allowlist. They also carry scopes such as posts:read, posts:write, and analytics:read. A scope limits what a token may do; it never grants access to a workspace that the token owner no longer manages.

Bearer header

Send the token in the Authorization request header using the Bearer scheme:
Start by listing the workspaces available to the token:

Workspace access

Workspace resources use the workspace ID in the path:
The API verifies all three conditions on every request:
  1. The token is active and not expired.
  2. The workspace is included in the token’s allowlist.
  3. The token owner is still an active owner or manager of the workspace.
An unavailable workspace returns 403 Forbidden. Passing a resource ID from another workspace does not bypass this check.

Scopes

Missing required permissions return 403 Forbidden with the required scope names.

Token lifecycle

The raw token is shown once when it is created. PostlyBee stores only its SHA-256 hash. From Settings you can review its prefix, scopes, workspace access, expiration, and last-used time, or revoke it immediately.
Store tokens in a managed secret store. Never expose them in browser code, query strings, public repositories, screenshots, or client-side logs.
Public API tokens and OAuth-issued MCP access tokens both use the Bearer header, but they are different credentials and cannot be interchanged.
Last modified on August 26, 2026